Headline figure
78%
of CISOs name AI management as the number one challenge in 2026
Source: ISMS Forum, Cyber Security and Data Protection Challenges 2026 (Spanish CISO survey); cross-checked with Fujitsu 2026 Cybersecurity Predictions.
2026 figures on Spanish CISO strategic priorities, cross-read with SOC-CMM and the implications for audit, board and investment planning.
Headline figure
78%
of CISOs name AI management as the number one challenge in 2026
Source: ISMS Forum, Cyber Security and Data Protection Challenges 2026 (Spanish CISO survey); cross-checked with Fujitsu 2026 Cybersecurity Predictions.
The Spanish CISO survey by ISMS Forum places AI management (78%) and cybersecurity regulatory compliance (DORA, NIS2, CERT, eIDAS, CRA, at 64%) as the two most critical challenges for 2026. Third-party risk management (56%), data privacy and sovereignty in AI and cloud (36%), post-quantum cryptography readiness (36%) and ransomware (34%) complete the top half. Fujitsu reinforces this read: AI governance will be discussed in boardrooms and IT/OT convergence will accelerate with NIS2 as a baseline requirement.
For a SOC, the useful reading is not replicating the ranking but mapping it: each CISO priority translates into operational evidence by SOC-CMM domain. AI management lands in Process, Technology and Services; regulatory compliance connects directly to Business and reporting; third-party risk is documented in Services and Business. Without that translation, the ranking is just a headline.
| Metric | Value | Reading |
|---|---|---|
| AI management | 78% | Top challenge. |
| Regulatory compliance (DORA, NIS2, CERT, eIDAS, CRA) | 64% | Compliance embedded in operations. |
| Third-party risk management | 56% | Supply chain as a pillar. |
| Data privacy and sovereignty in AI and cloud | 36% | Tied with post-quantum. |
| Post-quantum cryptography readiness | 36% | Harvest now, decrypt later risk. |
| Ransomware | 34% | Persistent but no longer top-3. |
| Human risk and insider threats | 32% | Behavioral analytics as response. |
| Cyber resilience and incident recovery | 28% | Connects to Services. |
| Executive responsibility and cyber governance | 22% | Rising board accountability. |
| Geopolitical cyber risks | 22% | Adapted threat modelling. |